First published: Sat Nov 09 2019(Updated: )
IBM Cognos Analytics is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or cause the web server to make HTTP requests to arbitrary domains.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | =11.0.0 | |
IBM Cognos Analytics | =11.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-1721.
IBM Cognos Analytics 11.0 and 11.1 are affected by CVE-2018-1721.
The severity of CVE-2018-1721 is high.
The CWE ID for CVE-2018-1721 is CWE-91.
A remote attacker could exploit CVE-2018-1721 to expose sensitive information or cause the web server to make HTTP requests to arbitrary domains.